Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware02 Aug 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALunder attack02 Aug 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware01 Aug 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack01 Aug 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23333CRITICAL01 Aug 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALunder attackransomware01 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
Metasploit600
Eramba (up to 3.19.1) Authenticated Remote Code Execution Module
CVE-2023-3625501 Aug 2023
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar
30RISK
open
GitHub PoC1
Nmap script to exploit CVE-2023-35078 - Mobile Iron Core
CVE-2023-35078CRITICALunder attackransomware01 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC14
Mehran-Seifalinia/CVE-2023-37979
CVE-2023-37979HIGH01 Aug 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open
GitHub PoC
Unauthenticated Command Injection in Cacti <= 1.2.22
CVE-2022-46169CRITICALunder attack01 Aug 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
CVE-2022-1388 - F5 Router RCE Replica
CVE-2022-1388CRITICALunder attackransomware01 Aug 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC2
Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability
CVE-2023-23333CRITICAL01 Aug 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
Exploit-DBVexDay Proof
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
CVE-2023-39147webappsphp31 Jul 2023
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
23RISK
open
GitHub PoC
timsonner/cve-2014-0160-heartbleed
CVE-2014-0160HIGHunder attack31 Jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALunder attackransomware31 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack31 Jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL31 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC3
Perform With Mass Remote Code Execution In SPIP Version (4.2.1)
CVE-2023-27372CRITICAL31 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC5
Tools to scanner & exploit cve-2023-35078
CVE-2023-35078CRITICALunder attackransomware31 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864631 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
Metasploit600
Maltrail Unauthenticated Command Injection
CVE-2025-34073CRITICAL31 Jul 2023
stamparm/maltrail <=0.54 Remote Command Execution
63RISK
open
Metasploit600
RaspAP Unauthenticated Command Injection
CVE-2022-3998631 Jul 2023
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma
60RISK
open
GitHub PoC
Easy and non-intrusive script to check for CVE-2023-35078
CVE-2023-35078CRITICALunder attackransomware31 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC
GeoServer OGC Filter SQL Injection Vulnerabilities
CVE-2023-25157CRITICAL31 Jul 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
infoleak
CVE-2023-3864630 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864630 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864630 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC1
#comeonits2023 #ie9 #Storm-0978
CVE-2023-36884HIGHunder attackransomware30 Jul 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
cashapp323232/CVE-2023-2868CVE-2023-2868
CVE-2023-2868CRITICALunder attack30 Jul 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
GitHub PoC
Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)
CVE-2022-26134CRITICALunder attackransomware30 Jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 480 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.